Security
How Strattum handles your enterprise data
Your enterprise data does not pass through Strattum servers. Connectors run in your environment. The policy engine operates on query metadata only. Every context request is logged with full field detail for compliance review.
Access Controls
Policy-first access model
Access policies define what each agent can query, from which connector, down to the field level. No query executes without passing policy validation. No agent holds raw data source credentials.
Per-agent identity binding
Policies bind to a specific agent identifier using OIDC token validation or API key. An agent cannot impersonate another or inherit a broader policy scope than its own.
Per-connector scope
Each allow rule specifies a connector, and optionally a schema, table, or field list. Scope declarations are explicit: anything not declared is denied by default.
Read-only enforcement
Connectors are mounted in read-only mode at the driver level. No write path exists through the connector, regardless of policy configuration.
Data classification labels
Classification tags from source systems (sensitivity levels, PII flags, data domain labels) flow through the policy engine. Rules can reference tags directly without requiring the agent to know the classification logic.
Policy versioning
Every policy change is versioned with timestamp, editor identity, and a diff view. Historical policy versions are retained and linked to audit events for the time period they were active.
Credential isolation
Service credentials for each data source are stored in the connector vault and never exposed to agents or through the API. Agents receive scoped query tokens only.
Compliance Posture
Built with compliance controls in mind
Strattum is designed with the controls that regulated enterprises need to complete their own compliance programs. We do not claim certification at this stage: we are a bootstrapped company in early access. What we ship is the architectural foundation that compliance programs require.
Access log retention, least-privilege query design, credential isolation, and audit event schemas that are compatible with standard SIEM ingest are all built in by default, not configured as optional add-ons.
The audit event schema maps to SOC 2 CC6 access review requirements, ISO 27001 A.9 logical access controls, and standard SIEM ingest formats. When your auditors ask what data an AI workflow accessed and under what authorization, the log is structured to answer that question without additional forensic reconstruction.
Access log retention
7-day retention on Starter, 90-day on Team, configurable on Enterprise. Logs are append-only and tamper-evident.
Least-privilege query design
Default-deny policy model. Every scope must be explicitly declared. There is no "admin access" mode that bypasses the policy layer.
SIEM-compatible audit schema
JSON event stream with standard field naming. Compatible with Splunk, Elastic, and Datadog ingest configurations without transformation.
Credential isolation
Source credentials are stored in the connector vault, not in agent configuration or API responses. No credential material is logged.
Audit Trail
What every audit event records
Every context request generates a structured event in the audit store. The event record contains enough information to answer an access-review question from an auditor without requiring custom log parsing.
Agent identifier
The agent ID that submitted the context request, bound to the policy that was evaluated.
Query scope
Connector, object or schema, and field list that were requested. Not the raw data returned.
Policy rule applied
Which policy rule matched, and the resolution: allowed, denied, or partially filtered.
Timestamp and duration
Millisecond-precision timestamp in UTC. Query execution duration for performance monitoring.
Export formats
JSON event stream
Continuous event feed compatible with Splunk HEC, Elastic Beats, and Datadog Logs ingest. Field names follow RFC 5424 where applicable.
CSV summary report
Flat-file summary with one row per context request. Suitable for access review spreadsheets and compliance deliverables. Scheduled or on-demand export.